Exploited Known exploited (KEV) Ransomware use CVE-2025-0282

Hunt, remediate, then update before it goes back — the sequence set for Ivanti

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Added to KEV Jan 8, 2025 Federal remediation due 2025-01-15

For the stack-based buffer overflow in Ivanti Connect Secure and related gateways, CISA set out conducting hunt activities, taking remediation actions where applicable, and applying updates before a device returns to service.

Key facts

  • CVE IDCVE-2025-0282
  • Affected (vendor / product)Ivanti Connect Secure, Policy Secure, and ZTA Gateways
  • CWECWE-121
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2025-01-15 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • CVE-2025-0282 is a stack-based buffer overflow in Ivanti Connect Secure, Policy Secure and ZTA Gateways.
  • The flaw can lead to unauthenticated remote code execution.
  • The required action covers going out to look for signs of intrusion, acting on what that turns up where there is something to act on, and putting updates on before a device is allowed back into service.
  • The update comes last, so a device stays out of service until hunting and remediation are complete.
  • Listed 8 January 2025 with a due date of 15 January, a window of seven days; among the 1,579 entries without an article this site holds as of 2026-09-05, only 17 carry seven days.

1The words before returning to service

This instruction carries a condition of timing. The update is to be applied before the device goes back into service. Put the other way round, the device does not return until hunting and remediation are done.

2Three tasks, in order

  1. 1Conduct hunt activitiesLook actively for signs that a compromise has already occurred
  2. 2Take remediation actionsWhere applicable, meaning where the hunt found something
  3. 3Apply updatesOnly after the preceding steps, apply the update
  4. 4Return to serviceThe device goes back only once the update has been applied

The update comes last, which sets this entry apart from the others. Ordinarily the update is the first thing done. Here hunting comes first and the update becomes the step immediately before return to service.

3Why that order

The aspectThe usual orderThe order set here
First stepApply the updateLook for signs of compromise
Where the update sitsFirstImmediately before return to service
The device meanwhileStays in serviceStays out until hunting and remediation are done
Assumption behind itExploitation may comeSomeone may already be inside

Hunting after the fact risks losing the traces to the update itself. If evidence of intrusion is overwritten in the course of updating, the means of establishing what happened goes with it. Placing the update last reads as a way of protecting that order.

4Seven days

Of the 1,695 records this site holds as of 2026-09-05, those without an article1,579Only 17 carry a window of seven days
Of those, entries recorded as known in ransomware use31720.1%
The window hereSeven daysListed 8 January 2025, due 15 January 2025

Seven days to hunt, remediate, update and return to service. Against the work asked for, the time allowed sits on the short side. The next article takes up an entry that did not ask for a fix at all.

Why it matters

Applying the update first is the usual order, but where compromise is likely to have happened already that order can destroy the traces. Placing the hunt first and the update immediately before return to service reads as a design for keeping the means of establishing what happened. When an instruction carries a condition of timing, there is a reason the order has to hold.

FAQ

Why does hunting come before updating?
The catalog gives no reason, but applying an update first risks overwriting traces of intrusion and losing the means of establishing what happened.
What does where applicable mean?
It refers to cases where the hunt turns up signs of compromise, in which remediation actions are then required.
When may a device return to service?
The instruction places return after hunting, remediation and the application of updates.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#CISA#United States#Cybersecurity
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.